VulnSea

CWE-918

CVEs classified under CWE-918, newest first.

840 CVEsRSS

CVE-2026-15189Medium· 6.3
2mo ago

A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23

A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-0285Medium· 4.9
2mo ago

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.43%via NVD
CVE-2026-53727High
2mo ago

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

▾ Twilightcss_parser · css_parserEPSS 0.51%via GHSA
CVE-2026-59702Critical· 9.3PoC
2mo ago

repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file://…

▾ Abyssalrepomix · repomixEPSS 0.44%via CVEORG
CVE-2026-59707High· 8.6PoC
2mo ago

LocalAI - Server-Side Request Forgery via POST /models/apply

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to galle…

▾ MidnightLocalAI · LocalAIEPSS 0.48%via CVEORG
CVE-2026-50127Medium· 5.9
2mo ago

Weblate SSRF: outbound URL guard misses some private ranges

Weblate SSRF: outbound URL guard misses some private ranges

▾ Sunlitweblate · weblateEPSS 0.47%via GHSA
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-34225Medium· 4.3
2mo ago

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-33655High· 7.7
2mo ago

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.44%via GHSA
GHSA-qrwj-vh9x-gw5vHigh· 8.3
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

▾ Twilightcoder · github.com/coder/coder/v2via GHSA
CVE-2026-55787High· 7.1
2mo ago

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

▾ Twilightflyto-core · flyto-corevia GHSA
CVE-2026-57987Medium· 6.5
2mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.87%via CVEORG
CVE-2026-58278Medium· 5.4
2mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.40%via CVEORG
CVE-2026-57993High· 7.4
2mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.88%via CVEORG
CVE-2026-22874Critical· 9.6PoC
2mo ago

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

▾ AbyssalEPSS 0.46%via NVD
CVE-2026-10055High· 8.5
2mo ago

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-11397Medium· 5.5
2mo ago

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-45499Critical· 9.9
2mo ago

Azure OpenAI Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Open AIEPSS 0.78%via CVEORG
CVE-2026-57100Critical· 9.9
2mo ago

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Entra Provisioning ServiceEPSS 0.78%via CVEORG
CVE-2026-9557Medium· 6.4
2mo ago

Mautic Focus component Vulnerable to SSRF

Mautic Focus component Vulnerable to SSRF

▾ Sunlitmautic · mautic/coreEPSS 0.23%via GHSA
CVE-2026-50288High
2mo ago

@asymmetric-effort/specifyjs: URL parse failure silently allows request

@asymmetric-effort/specifyjs: URL parse failure silently allows request

▾ Twilightasymmetric-effort · @asymmetric-effort/specifyjsEPSS 0.48%via GHSA
GHSA-xw57-23p8-9wc5Medium
2mo ago

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-2944-57xv-2682Medium
2mo ago

@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction

@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-j5qp-p44g-2m49Medium
2mo ago

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
CVE-2026-53812Medium· 7.7
2mo ago

OpenClaw's browser act interactions could bypass private-network navigation checks

OpenClaw's browser act interactions could bypass private-network navigation checks

▾ Sunlitopenclaw · openclawEPSS 0.39%via GHSA
CVE-2026-50151Medium· 5.9
2mo ago

oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
GHSA-97vg-427p-8hx5Medium· 6.4
2mo ago

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-44936Medium· 5.0
2mo ago

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

▾ Sunlitrancher · github.com/rancher/fleetEPSS 0.35%via GHSA
CVE-2026-48978Low
2mo ago

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

▾ Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA
CVE-2026-11714High· 8.5
2mo ago

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

▾ Twilightibm · websphere_application_serverEPSS 0.36%via NVD
CWE-918 vulnerabilities (CVEs) — page 22 · VulnSea